Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-13509

Опубликовано: 18 июл. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they resend the secret.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:docker:docker:*:*:*:*:enterprise:*:*:*
Версия от 18.09.0 (включая) до 18.09.8 (исключая)
cpe:2.3:a:docker:docker:17.03.2:1:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:2:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:3:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:4:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:5:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:6:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:7:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:8:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:1:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:10:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:11:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:12:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:13:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:15:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:16:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:17:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:18:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:19:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:2:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:20:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:21:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:22:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:3:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:4:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:5:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:6:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:7:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:8:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:9:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:1:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:2:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:3:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:4:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:5:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:6:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:7:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:8:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:9:*:*:enterprise:*:*:*
Конфигурация 2
cpe:2.3:a:docker:docker:*:*:*:*:community:*:*:*
Версия до 18.09.8 (исключая)

EPSS

Процентиль: 86%
0.03175
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they resend the secret.

CVSS3: 6.5
redhat
около 6 лет назад

In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they resend the secret.

CVSS3: 7.5
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 7.5
debian
около 6 лет назад

In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06. ...

CVSS3: 7.5
github
больше 3 лет назад

Secret insertion into debug log in Docker

EPSS

Процентиль: 86%
0.03175
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-532